What the evidence shows
Senate testimony, regulatory findings, peer-reviewed research and the companies' own admissions carry every claim on this site. All public. All verifiable. Start anywhere.
What a public school Facebook Page exposes children to right now
Six documented exposures. Every one sourced. Every one starts with a photo that anybody can reach.
| Exposure | Status | Source |
|---|---|---|
| Strangers harvest school imagery and build accounts that target the school | Documented | 100+ reports to eSafety, Jan to Mar 2026, almost all involving imagery harvested from school social media or websites |
| Meta trains AI on children's photos | Confirmed | Admitted under oath, Australian Senate, Sept 2024 |
| Facial recognition companies scrape the photos | Confirmed | 50B+ images. OAIC found breach of Privacy Act |
| Australian children turn up in AI training datasets | Confirmed | 362 AU children in <0.0001% sample (HRW, July 2024) |
| People generate deepfakes from school photos | Active threat | 50+ Melbourne schoolgirls, June 2024. Reports doubling. |
| Search engines index the Page and everything on it | Confirmed | Standard for all public Facebook Pages |
What keeps those pages public
Three gaps, and not one of them is a technology problem. These are the reasons the exposures above keep happening, and each one sits inside somebody's authority to close.
| Gap | Status | Source |
|---|---|---|
| NSW requires open school accounts while eSafety advises restricting them | Current | eSafety advisory 28 July 2026 against PD-2011-0418-01 |
| The form parents sign predates every exposure above | Systemic | Binary choice. No AI disclosure. No expiry. |
| No code yet sets rules for children's data of this kind | Growing | Children's Privacy Code due December 2026 |
Conflicting Advice
On 28 July 2026 the eSafety Commissioner told schools to move student imagery into a closed or restricted space. NSW Department of Education policy requires the opposite. Both documents, quoted side by side.
No Consent
The NSW form gives parents one binary choice: all public publishing or nothing. It mentions no AI training, no facial recognition and no deepfakes. Somebody wrote it before any of this existed.
The System
The policy that requires public accounts, the consent form that predates AI, the laws that have not caught up, and the timeline of what changes next.
The evidence in detail
Five threads, newest first. Click through for the full evidence.
Harvested Imagery
Straight from the regulator: eSafety counted 100-plus reports in a single quarter about anonymous accounts targeting schools, almost all built from imagery taken off school social media or websites.
AI Training
Meta confirmed under oath to the Australian Senate that it scrapes every public post since 2007 to train AI. That includes children's photos. Australians get no opt-out.
Facial Recognition
Clearview AI scraped 50 billion+ photos from Facebook for facial recognition. The Australian Information Commissioner found it breached the Privacy Act. The database grew after the deletion order.
Deepfakes
AI-generated explicit images of 50+ schoolgirls at a Melbourne school. Created from publicly accessible photos. Deepfake reports to the eSafety Commissioner are doubling year on year.
Training Datasets
Human Rights Watch found 362 identifiable Australian children in a single AI dataset, from less than 0.0001% of the data. Some photos came from school uploads.
Ready to act?
The evidence is clear. The fix is one clause in one departmental procedure, and the department can change it without legislation.